Malware

Win32/GenCBL.DKX removal guide

Malware Removal

The Win32/GenCBL.DKX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.DKX virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the NetSupport malware family
  • Detects Bochs through the presence of a registry key
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/GenCBL.DKX?


File Info:

name: E9438DA9AE361C2FC0D6.mlw
path: /opt/CAPEv2/storage/binaries/5f953d36c01f17523ac35b57219b51bdd98d79ff0bd6d8f28f31e66c0d20e06e
crc32: A15CD167
md5: e9438da9ae361c2fc0d6f407b1383519
sha1: 7c5fecc4833dbf8986d49378685854105302029e
sha256: 5f953d36c01f17523ac35b57219b51bdd98d79ff0bd6d8f28f31e66c0d20e06e
sha512: 44dc2eae36883b0dbedf726fa9d5f1672095132bcd803200bd4cc2baed97c5ab2f85e566d6de2a4156428ec9fcede2b2cb38863d6e32d47c96a10bf7188b6917
ssdeep: 49152:VKG3z+STTgm/qt/9Zf6boLzy3+UEClKO6ETgu6:VKyz/gm/wjf1Sl8sgu6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1A523763392C431EC5A043299FC83925E78FC3156FAA987BB441B292FB13A0C755B5B
sha3_384: 3ebc8c7e60b3e2c033c396144299fb8a0e8d0c45383c6a13081efccc00532eebfeabd893245743e038c53cfccf0328a3
ep_bytes: e885630000e978feffff8bff558bec56
timestamp: 2014-12-02 10:07:30

Version Info:

0: [No Data]

Win32/GenCBL.DKX also known as:

BkavW32.Common.24D7B5EB
LionicTrojan.Win32.ChePro.7!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanAdware.GenericKD.61004862
FireEyeAdware.GenericKD.61004862
SkyhighNetsupportrat.d
McAfeeArtemis!E9438DA9AE36
Cylanceunsafe
ZillyaTool.NetSup.Win32.119
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanBanker:Win32/ChePro.f5ff91e4
K7GWRiskware ( 00584baa1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenCBL.DKX
ZonerTrojan.Win32.153309
KasperskyTrojan-Banker.Win32.ChePro.njjz
BitDefenderAdware.GenericKD.61004862
AvastWin32:Trojan-gen
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/AD.Nekark.yxytb
DrWebBackDoor.RMS.219
VIPREAdware.GenericKD.61004862
EmsisoftAdware.GenericKD.61004862 (B)
GDataWin32.Riskware.NetRemote.A
JiangminRemoteAdmin.NetSup.ai
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/AD.Nekark.yxytb
KingsoftWin32.Troj.Banker.a
XcitiumMalware@#27zmrbmx8fz67
ArcabitAdware.Generic.D3A2DC3E
ZoneAlarmTrojan-Banker.Win32.ChePro.njjz
MicrosoftTrojanDownloader:Win32/CryptInject!MSR
VaristW32/S-f514affe!Eldorado
VBA32Riskware.NetSupport
ALYacAdware.GenericKD.61004862
MAXmalware (ai score=100)
MalwarebytesGenCBL.Ransom.FileCryptor.DDS
PandaTrj/CI.A
RisingPUF.RemoteAdmin!1.E606 (CLASSIC)
YandexRiskware.RemoteAdmin!zKwO6DNnIh8
IkarusTrojan.RAT.Netsupportmanager
MaxSecureTrojan.Malware.205915480.susgen
FortinetRiskware/RemoteAdmin
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Win32/GenCBL.DKX?

Win32/GenCBL.DKX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment